{"id":"USN-2753-1","summary":"lxc vulnerability","details":"Roman Fiedler discovered a directory traversal flaw in lxc-start. A local\nattacker with access to an LXC container could exploit this flaw to run\nprograms inside the container that are not confined by AppArmor or expose\nunintended files in the host to the container.\n","modified":"2026-04-22T09:17:15.281642Z","published":"2015-09-29T16:15:44Z","related":["UBUNTU-CVE-2015-1335"],"upstream":["CVE-2015-1335","UBUNTU-CVE-2015-1335"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-2753-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-1335"}],"affected":[{"package":{"name":"lxc","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/lxc@1.0.7-0ubuntu0.5?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.7-0ubuntu0.5"}]}],"versions":["1.0.0~alpha1-0ubuntu11","1.0.0~alpha2-0ubuntu1","1.0.0~alpha2-0ubuntu3","1.0.0~alpha2-0ubuntu4","1.0.0~alpha2-0ubuntu5","1.0.0~alpha2-0ubuntu6","1.0.0~alpha3-0ubuntu1","1.0.0~alpha3-0ubuntu2","1.0.0~alpha3-0ubuntu3","1.0.0~alpha3-0ubuntu4","1.0.0~alpha3-0ubuntu5","1.0.0~alpha3-0ubuntu6","1.0.0~alpha3-0ubuntu7","1.0.0~alpha3-0ubuntu8","1.0.0~beta1-0ubuntu1","1.0.0~beta1-0ubuntu2","1.0.0~beta1-0ubuntu3","1.0.0~beta2-0ubuntu1","1.0.0~beta2-0ubuntu2","1.0.0~beta3-0ubuntu1","1.0.0~beta4-0ubuntu1","1.0.0~beta4-0ubuntu2","1.0.0~rc1-0ubuntu2","1.0.0~rc3-0ubuntu1","1.0.0~rc4-0ubuntu1","1.0.0-0ubuntu1","1.0.0-0ubuntu2","1.0.0-0ubuntu3","1.0.0-0ubuntu4","1.0.1-0ubuntu1","1.0.2-0ubuntu1","1.0.2-0ubuntu2","1.0.3-0ubuntu1","1.0.3-0ubuntu2","1.0.3-0ubuntu3","1.0.4-0ubuntu0.1","1.0.5-0ubuntu0.1","1.0.6-0ubuntu0.1","1.0.7-0ubuntu0.1","1.0.7-0ubuntu0.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"liblxc1","binary_version":"1.0.7-0ubuntu0.5"},{"binary_name":"lxc","binary_version":"1.0.7-0ubuntu0.5"},{"binary_name":"lxc-templates","binary_version":"1.0.7-0ubuntu0.5"},{"binary_version":"1.0.7-0ubuntu0.5","binary_name":"lxc-tests"},{"binary_name":"python3-lxc","binary_version":"1.0.7-0ubuntu0.5"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2015-1335","severity":[{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:14.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2753-1.json"}}],"schema_version":"1.7.5"}